Showing posts with label Antivirus. Show all posts
Showing posts with label Antivirus. Show all posts

Sunday, September 27, 2015

Cryptowall is back on the prowl, so watch your back...


Back in 2014, a nasty virus called "Cryptowall" reared its unsightly head in the computer world, and it proceeded to leave a fair deal of pandemonium in its wake.
Of course once antivirus definitions the world over became aware, the threat was largely eradicated and peace reigned in the Kingdom of CPU.

These things are like a bad rash though, and there has of late been a resurgence of this particular bad boy on PC's all over the place.
Hell, Carte Blanche even featured an article on the virus a few weeks back - I'm sure the wonderfully talented humans who coded it must be awfully proud! Well done guys! 

Anyway, back to the post - in short, watch your back as you normally would when dealing with the internet, email, flash drives from other PC's, pretty much as you would do when walking down a dark alley at night.
This particular threat entices the hapless victim by means of links on dodgy sites, links within the attachments of spam mails and a variety of other sneaky tactics.
Once the user clicks on the link, if not stopped by an antivirus, the virus will then initiate and continue to install itself in memory, and as a startup item on the infected PC.

Symptoms of Cryptowall (how you know that you are infected...):

  • Cryptowall scans the PC for folders which contain your meaningful data - here we are talking about the Desktop folder, My Documents etc.
    It also scans mapped network drives - these will become infected as well, but only specifically mapped drives.

  • Next, it encrypts every "work" file that it finds - this includes Word documents, Excel documents and PDF documents, among others.

  • Finally, it dumps approx. 4 files into every folder that it has encrypted, named "HELP_DECRYPT.ext" - each of these files provides instructions on how to decrypt your data, and it's pretty simple - pay up. Yup, all this virus amounts to is extortion.
    The variation of the infection that I recently dealt with wanted payment in Bitcoins, but I'm sure they take Diners Club, AMEX, VISA and many other forms of payment too :)

  • Any attempt to now open an encrypted file will result in a generic program error, as if the data within the file is corrupted.
    At this point, panic may set in.
    This is justified, since there is no way to decrypt the files without paying up, unless you have a recent intact backup of your files. Do not plug your backup drive in, until you are 100% sure that your PC is clean again.
    For a very technical rundown of the threat, including cleaning and recovery options, check out:
    http://www.bleepingcomputer.com/virus-removal/cryptowall-ransomware-information
You DO NOT want to see these files on your hard drive...
So in essence it's a pretty simple virus, but the impact that it can have on a business with a lot of data is HUGE.
After going through a rough few days taking one of these bad boys down recently, my advice to end users is simple - protect yourself in every possible way, and that isn't limited to antivirus software.
Sure, getting yourself a great antivirus like Avast is a non-negotiable, however always tread carefully when making use of a public domain like the internet.

Watch where you browse. 
Triple check who sent you that not-so-kosher looking email.
Don't click on that link in the body of a "banking" email, and if you do end up being on the very unfortunate receiving end of one of these, make sure that your data is backed up somewhere off your PC - preferably on an external drive.

Wednesday, October 20, 2010

Can you be TOO secure when it comes to internet banking and viruses?

Of late, South African banks have stepped up their efforts to stop internet banking fraud, by introducing a number of 3rd-Party applications that are supposed to protect the end-user from potential threats.

The ones that I have encountered include Prevx (FNB) and Rapport (Nedbank), and they add an additional layer of protection onto your web browser, specifically targeted at protecting internet banking sessions.
End-users will happily install whatever the bank recommends, because in doing so, the end-user then has grounds to claim, should their account be hacked or breached in any way.
If an end-user has done everything that their bank has advised in order to stay safe online, then it minimizes any responsibility placed upon them, should the proverbial sh1t ever collide with the proverbial fan...

Now this is all fine and well, one might say. Anything in the name of security!
Then I inevitably get a call, and it goes something like this:

Caller: My PC is running really slowly lately...


Me: What has changed on your PC recently that may have caused it? Have you installed anything new? Changed anything?


Caller: Nope, just installed this banking software thing to protect me when I am online...


Me: Ah. Ok, and what other antivirus protection etc. is running?


Caller: ....dunno.


The call out that follows, invariably involves the discovery of one or more of the following software packages installed:

- Prevx
- Rapport
- Some antivirus (Avast, Norton's, BitDefender...)
- Windows Defender

The important thing to remember here is that each new antivirus / anti-spam / security package that gets installed on a PC, does 2 main things:


- It tries to protect you, and in doing so it scans opened files, web pages, RAM, folders on your hard drives, flash drives that you may plug in etc.
- In the process of trying to protect you, it uses system resources - i.e. RAM and CPU mainly.

Ultimately, trying to be as secure as possible on the internet is a delicate balancing act between safety and speed.
It is also not necessarily true that more is better - I have seen antivirus software identifying banking protection software as a virus... go figure...?!
So, in addition to speed concerns, you could end up with an arm-wrestling match between different software packages. It can become quite confusing!

As a guideline, I would say that one antivirus package, coupled to a single internet banking protection package should be sufficient.
If you happen to bank with different institutions who each want you to install THEIR preferred software, then you have a dilemma on your hands, because you are likely to end up with an antivirus package (assuming you already have one), and 2 or more packages aimed at protecting your online banking experience = potentially slow PC... :)
Enhanced by Zemanta

Tuesday, February 23, 2010

How to get infected while browsing the internet... a DIY guide!

Despite the presence of antivirus software, firewalls and anti-spam software, many people still fall for the sneaky tricks of virus-spreaders online all the time.
Avast - my antivirus software of choice (and it's free!)
AVG - another decent free antivirus program

One of the tricks I have come across of late happens when the webpage that loads, looks exactly like a Windows Explorer window, which (apparently) shows your hard drives, DVD Drives etc.
A fake "scan" then runs on top of this window and alleges that you are infected by millions of viruses and spyware.
The entire "scan" window is a giant hotspot, and at the end of the "scan" you are encouraged to click a link to fix the problem.
If the link is clicked, you then open yourself up to an actual threat, possibly a downloaded script, dodgy website or some other malicious means of infecting your PC.
Nicely done, you fiendish skanks...!

How to get your self into a fix... buying into this nonsense is a great way to get started!

So in order to get you to click on their dodgy links, they first play on the paranoia of being infected.
Once they have convinced the gullible user that they are in fact in some kind of grave danger, the paranoia then drives the user to click anything that promises to make it all better.

So what to do if you think this may have happened to you?
Well if you went ahead and clicked the link, you will no doubt know if you have been infected because you are probably being bombarded by a message along the lines of "Your system is being infecting by serious bad virus", or some other similarly dodgy message.

A key giveaway here is the unusual / incorrect usage / incorrect spelling of the English language - antivirus companies like to uphold a professional image and appearance, by using well constructed sentences, perfect spelling, and by following the general rules of a language.
Virus creators on the other hand, despite their allegedly massive levels of intelligence, cannot seem to grasp the very basics of how one puts a proper sentence together. Spelling too, it seems is beyond their primitive level of understanding.

If you are infected, get yourself a free copy of Avast or AVG fast...

Monday, January 25, 2010

Download the new version of Avast (free) now...

Over the years I have used many different antivirus packages, some good, some dodgy.
I often get asked which is the best one to use, and to answer this you need to think about several things:

- Price
- Effectiveness (does it perform?)
- Resource Requirements (how slow will your PC run after you install the antivirus software?)
- Ease of use (how confusing is it to setup and operate?)

After many trials and tribulations, much experimentation, and plenty of frustration, I can safely say that Avast Antivirus comes out on top repeatedly.



First off, Avast (Home Edition) will set you back a total of ZAR0. Zip. Free to download at http://www.avast.com/free-antivirus-download.

Secondly, I have found Avast to be the most effective in removing infections. "Ah but if it's so good then why did the infection get through in the first place?" I hear you ask...
Well surprisingly, viruses can get past most antivirus software if given half a chance. Let's say you skip your updates for a day, a week... maybe a month. That's a window of opportunity right there, to mention only one possible scenario.

Most of the problems I have dealt with in the past are post-infection, i.e. I am called in once the PC has already been infected, despite Nortons, BitDefender, etc. etc. running in the background.
That's where Avast shines - thanks to its boot time scan you can run a virus scan before Windows even starts, and therefore before the virus gets a chance to load into memory.

Thirdly, Avast does not significantly impact the performance of the machine that it is running on.
I am not going to go into the notorious resource-hogging habits of some of the other reputable and well-known antivirus packages, but it is fair to say that a lot of antivirus software kills machine performance.

Fourthly, Avast is setup to go out of the box (not that it comes in a box... you download it :)) - just install it and you are good to go.
The default configuration is perfect for most PC's, and it will give you decent protection from the get-go.

Avast has just released Version 5 of their antivirus software, with revamped graphics, new features and other updates to the software.
Get it here now.

Grab your inverter now and be prepared for Load Shedding!

Shop HP Printers here!

Low on ink? Shop Genuine HP Ink and Toner here!

Shop Targus laptop bags, USB hubs, accessories and gadgets here!

Popular Posts